The short answer: the free consumer version of Google Drive cannot be used for PHI, because Google does not make a business associate agreement (BAA) available for personal accounts, and no service can hold protected health information (PHI) without one. Google Drive inside a paid Google Workspace domain is different: Google lists Drive among the services that can be covered under the Google Workspace BAA, which makes compliant use possible, provided the BAA is actually executed and the domain is configured with discipline.
"Is X HIPAA compliant" is never really a question about the software. It is a question about the contract, the configuration, and the workflow. Here is the full answer for Drive.
The Rule That Decides It
Under HIPAA, a vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity is a business associate, and the covered entity must have a signed business associate agreement in place before PHI touches the service (45 CFR 164.502(e); 164.308(b)). The BAA binds the vendor to the Security Rule's safeguards and breach notification duties. Cloud storage is the textbook case: the Office for Civil Rights' own cloud computing guidance treats a cloud storage provider holding PHI as a business associate even when the data is encrypted and the vendor never views it.
Apply that to Drive's two worlds:
| Version | BAA available? | HIPAA status |
|---|---|---|
| Google Drive on a free @gmail.com account | No | Cannot hold PHI; consumer terms, no HIPAA obligations |
| Google Drive in paid Google Workspace | Yes, coverable under the Workspace BAA | Compliant use possible once the BAA is executed and the domain configured |
The BAA is not automatic with payment. A Workspace administrator must review and accept it in the admin console, and Google publishes the list of covered services for eligible editions. A practice that pays for Workspace but never executed the BAA is legally in the same position as a free user. Our explainer on what a business associate agreement is covers why this document, not encryption, is the hinge.
What BAA Coverage Does Not Fix
Executing Google's BAA moves Drive into business associate territory. Four failure modes survive it:
- Personal accounts. Coverage follows the domain, not the person. A staff member saving a patient spreadsheet to their personal Drive is outside the BAA entirely, and consumer-account spillover is among the most common real-world HIPAA failures. Policy and technical controls both need to block it.
- Link sharing. Drive's "anyone with the link" setting turns a patient document into a public URL. The Security Rule's access control standard (45 CFR 164.312(a)) expects access limited to authorized users; domain administrators should restrict external sharing defaults and audit exceptions.
- Unmanaged sprawl. PHI scattered across personal folders, ungoverned shared drives, and forgotten spreadsheets defeats the access reviews and audit controls (45 CFR 164.312(b)) the Security Rule expects. Designate structured, access-controlled shared drives for anything patient-related.
- The program gap. A BAA is not a compliance program. Your risk analysis (45 CFR 164.308(a)(1)), workforce training, retention rules, and incident procedures remain yours. The tool can support compliance; only the program achieves it.
Configuration Checklist for Covered Drive
For a Workspace domain that will hold PHI:
- Execute the BAA in the admin console and confirm Drive appears in Google's current covered-services list for your edition. File the executed copy with your compliance records.
- Set sharing defaults to internal, disable "anyone with the link" for PHI drives, and restrict external sharing to allowlisted domains where genuinely needed.
- Structure shared drives by function with role-based membership, so access reviews are reviewable.
- Enforce managed accounts: block or discourage consumer-account use on work devices, and write the personal-account prohibition into policy.
- Enable two-step verification for every account touching PHI.
- Review audit logs periodically: Drive activity reporting exists precisely so unusual access is visible.
- Add Drive to the risk analysis and vendor inventory.
Drive Is Storage. Patient Communication Is a Different Problem
A covered Drive answers "where do patient documents live." It does not answer "how do patients receive and return them." Emailing Drive links from consumer Gmail reopens the uncovered-channel problem, the same analysis we walk through in Is Gmail HIPAA compliant?, and texting links introduces the TCPA (47 U.S.C. 227), which requires prior express consent for automated texts.
The pattern that works: the text or email carries a logistics-only nudge, "Your forms for Friday are ready: [link]", and the document sits behind authentication. Message bodies stay free of clinical content, consistent with the transmission-risk analysis the Security Rule requires (45 CFR 164.312(e)). The channel side of that architecture is covered in our pillar guide to HIPAA-compliant text messaging.
The Decision Framework
- Any patient information on a free @gmail.com Drive: stop. No BAA exists; migrate the files to covered storage, delete them from the consumer account, and document the remediation.
- Workspace domain, BAA executed, checklist complete: Drive is a reasonable, covered home for administrative PHI: intake packets, scanned forms, operational spreadsheets.
- Clinical records at scale: an EHR remains the right system of record; Drive covers the administrative periphery, not the chart.
- Patient-facing document exchange: pair covered storage with a consented, covered communication channel rather than emailing links ad hoc.
How OCR Thinks About Cloud Storage
The Office for Civil Rights evaluates programs, not products, and its cloud guidance plus enforcement history make the pattern clear: the cited failures are almost always the absence of a BAA with the storage vendor, the absence of a risk analysis covering the tool, or access left open, rather than sophisticated attacks. The audit questions for Drive are predictable: Is there an executed BAA? Does the risk analysis cover cloud storage? Are sharing settings restricted and reviewed? Can you produce access logs? Four yes answers make Drive a defensible part of the story. Any no is the finding.
This article is general information, not legal advice. Requirements vary by jurisdiction and change over time, so confirm your own obligations with qualified counsel or the relevant regulator.
Frequently Asked Questions
Does Google sign a BAA for Google Drive?
Yes, for paid Google Workspace editions. Google's Workspace BAA lists covered services, and Drive is among them for eligible editions. The administrator must accept the BAA in the admin console; it is not automatic with payment. No BAA is available for free consumer accounts.
Is it a HIPAA violation to store patient files on a personal Google Drive?
Storing PHI with a vendor that has no BAA is an impermissible arrangement under the business associate rules, and consumer accounts have no BAA. Practices that discover it should migrate the files, delete the consumer copies, document remediation, and assess breach notification duties with their privacy officer.
Is Google Drive encrypted enough for HIPAA?
Google encrypts data in transit and at rest, which supports the Security Rule's technical safeguards. But encryption never substitutes for the BAA: compliance is a legal status built on the contract, the configuration, and your program, not a cipher strength.
Can I share a Drive link with a patient?
Only with the sharing scoped to that authenticated recipient, never "anyone with the link," and only from a covered domain. Send the link through a consented channel with a logistics-only message body, keeping clinical detail inside the authenticated document.
Should a practice keep medical records in Drive instead of an EHR?
No. Drive under BAA suits administrative documents: forms, scans, operational files. The medical record belongs in an EHR designed for clinical documentation, audit, and retention. Use each system for what it is built for and cover both in the risk analysis.
Documents Covered, Communication Covered
FRANSiS handles the communication half: consented patient texting with a signed BAA included, logistics-only message design, and an AI Powered Helper managing replies, pairing cleanly with covered document storage. Contact us to close the channel gap.


